Skip to content

Releases: afterdarksys/secretserver-cli

Release list

v1.0.1

Choose a tag to compare

@straticus1 straticus1 released this 04 Oct 16:39

Changelog

  • ce0f10aa3c3d95e7e95c28db0c9de3aff248716a Merge pull request #5 from afterdarksys/fix/cli-version-name
  • dcd12e71dabfc2ea4757ff12fd3bd9bec64a01c1 Merge pull request #6 from afterdarksys/docs/cli-v1.0.1-notes
  • 7106437292a083820861a571535a5d93029355cf docs(cli): v1.0.1 release notes
  • 58e00f90521e77d57d004f2ec2c78ab12149305f fix(cli): ss version names the binary ss, not adkm

Install

macOS / Linux (curl):

curl -fsSL https://secretserver.io/install | sh

The installer verifies the archive against ss_1.0.1_checksums.txt.

Homebrew:

brew install afterdarksys/tap/secretserver-cli

Direct download: See assets below; verify with
shasum -a 256 -c ss_1.0.1_checksums.txt --ignore-missing.

v1.0.0

Choose a tag to compare

@straticus1 straticus1 released this 04 Oct 08:54

Changelog

  • 94c1350499fd49a469a87342c25f6cd17dc54623 Add encrypted PDF sharing backed by DarkStorage
  • 05b9ceff69aab05980521d333d58eb4243f974ab Add encrypted PDF sharing backed by DarkStorage
  • c9ff3bf3a8af4cb51be411dbb75ca79fdad953e0 Add landing page and Kubernetes deployment
  • e080cf1735b1d3fd61a3f6bfbd4521b83eb7ba58 Harden platform and add device enrollment and named secret variables
  • 8cc413307200c5c0db53d84b37b6c6adba87f670 Harden secret and document memory lifetimes with guarded buffers
  • fd259df0ba9f0d0d3cf4d9ec5ebe3524b61a63cf Harden secret and document memory lifetimes with guarded buffers
  • 4261f63b588dd18608c992495720a35c62b6288c Merge branch 'prod-readiness-2026-09-26' into prod-readiness-components
  • 8918e7e318ce32b44f0accf831ea98f9871fd86b Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
  • e194b4c7ddbfebdec05971cd56ffa1e476dee427 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
  • 8c1a204ebb1789b9361b60c79f4de45e66fe4001 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
  • cb8d81af1ecd446b85d8fbdaf2a56e51697594f9 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
  • 917bc42ab873b29bef6ac8df0249c68c6e2043f7 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
  • 4efa813c4d8682e9d71b582f5e140d46b13ff4a7 Merge branch 'prod-readiness-2026-09-26' into prod-readiness-web
  • 10f723feb7b4dc466a4bbcd5045ed82c4d3bbbc8 Merge branch 'site/wiring-audit' into site/web-refresh
  • 2cee976b4c0e40a0092034746fd3ae18cc8d75f4 Merge feat/cli-sso-login into release from main 64b23ff
  • 2b4c53646331febf40d58543a472f7720715c063 Merge pull request #2 from afterdarksys/fix/cli-distribution
  • 224b77892a9be231ef2a4f6584952d79c0bce8e0 Merge pull request #3 from afterdarksys/docs/cli-v1.0.0-notes
  • bfd7f76434ec1cfcad8f24535773ac411f66b80c Merge pull request #4 from afterdarksys/fix/cli-default-output
  • 8874962987f3f001f50bc4348ccf519b88a3b5b9 Merge release/cli-sso-login: CLI SSO login (production 2cee976)
  • ad954730e06a223261fa7796389e255828c96fa0 Merge remote-tracking branch 'origin/prod-readiness-2026-09-26' into prod-readiness-web
  • 9a9b6eb4450061d6f8f286725ca4ca3c0abdf3c6 Merge remote-tracking branch 'origin/prod-readiness-2026-09-26' into prod-readiness-web
  • 16d558822d5fea9415801f13a6e6487e23163991 Merge remote-tracking branch 'origin/prod-readiness-2026-09-26' into prod-readiness-web
  • f5272f2b3e018d42eeeef0d069d14edba3f826b9 Merge remote-tracking branch 'origin/prod-readiness-components' into integration-trial
  • b39f5cfe23b588fa34f2a383aaf2cdeea37d0880 Merge remote-tracking branch 'origin/prod-readiness-web' into integration-trial
  • 0c062063f9edfafe6a6dc279eafacf833acf14b0 Record verified integration revisions and deployment handoff
  • 9eeb4b53769ac2957391ff58eeefd5df2c474c66 Record verified integration revisions and deployment handoff
  • 9c8c2a382eab482027acf4ecd93eb2a5a9bd9ffd Record verified memory-hardening release revisions
  • ec6e60c54ad826f02f36aeed820181e9e9f4b11d Record verified memory-hardening release revisions
  • 360297bb845a257fa2255aed7ed14c93bfae5b1d Redesign website and console with themes and software documentation
  • a488bd379ca917f12bc5e5af1a30d940d3002261 Redesign website and console with themes and software documentation
  • 29bf307f8947af1e1f828318a4ea20ed99170cb6 build(deps): replace hashicorp/vault/shamir with an in-tree copy
  • 8e6b73094a45f07b5254940ea0deb881f4cfc5e5 build(deps): update google.golang.org/grpc to 1.83.2
  • a2a0e92150aed3942aa5a53a44b4fcd66fa28e25 build: Add Dockerfile and tidy dependencies
  • 793587521754180da3608adafce14ad02f2f1c11 build: add .dockerignore for the API image
  • f498d16a9ec1964ccc97a2b8b41d967e3bc76ac0 build: replace stale deploy scripts with build-only image scripts
  • c1b499272672842306e8bd3eb10a9ae88e344efb chore(cli): remove the unreachable cli/cmd/secrets package
  • 336d7e528fd62db0c37d588bdf264c1a080b791b chore(deploy): align k8s manifests with the image contract, drop dead ones
  • 2aee99642968fbe86c17e92dc37581e87a3450d4 chore(web): drop the unused OIDC build argument and API origin from CSP
  • a6f02e57e96c6e7d228c688651df6a4ef65d6239 crypto: PKCS#11 login outside the secure-memory lock, with a timeout
  • b5463f6887822f34fcbaafa4837e84018b3be73b crypto: PKCS#11 login timeout is fatal and abandons the session
  • 58083d492b68f0b0bd3c2acef439e90837ad89d7 deploy plan: isolated renderer, DarkStorage release branch, SNAT note
  • 4d795130784f71a154ad4d79ebe50dc0962756ea deploy plan: renderer latency measured in the final container
  • c90311850fbff5deb291207ea544d5d40242d513 deploy plan: separate renderer uids, liveness, TRUSTED_PROXIES, ptrace_scope
  • 8d57be803c741170d714c4b0e81068dbc06f6ea6 deploy/2026-09-28: prod run list, DB preflight/backup, local rehearsal
  • 3e050bd6176e1bb93679fff46855bcaf38302f2f deploy/2026-09-28: prod run list, DB preflight/backup, local rehearsal
  • 25cefbe775fcca3849532df007f4b7ea99baec10 deploy/2026-09-28: read-only check that the API's Vault token can write the SSO secret path
  • 6a4abcaba9517d010d413c0de8bfea13099c230a deploy/2026-09-28: read-only check that the API's Vault token can write the SSO secret path
  • ab13c89f07b2599238510e020a9b95097b35460d deploy: Vault check probes a minted tenant token; root is a warning
  • 73bfb88357fc4fe0c840bcd7a4a65ebf6aa2823c deploy: protected documents deployment plan and operator files
  • c01e6fb9876685bba70d49a0c5f780a34d3a08d2 deploy: run list for the CLI SSO release 2cee976 on apps (run 2026-10-04)
  • 69d60e628eacd0d28e81ad00eaa5a1d28b40200c deps: bump x/crypto, go-pkcs12, go-ntlmssp and lego to fixed versions
  • 4050e3f6d8cd7a4d8c7e9b220f723d7b031cffa5 docker: build the api-server package, not main.go alone
  • 7f12caf091d7fbd5c099ad93ed5461473bf26ee1 docs(cli): install/release docs; API keys via ss login or POST /api/v1/api-keys
  • 0914759c5e598ba931d471b5deeb8a5930dc3b14 docs(cli): state what ct, discover --import and import actually do
  • c5e8d298a6ac1e77abed22562f464acf943fcf59 docs(cli): v1.0.0 release notes are final
  • 7ac7bd5dd5b8d9370b497cedb7702f7cad77f4bd docs(planning): Phase 5 complete — mark ADM-01..09 and DIAG-01..05 done
  • c652bf6ffe496425a1c67611b4c5d82adf167300 docs(planning): Phase 6 complete — milestone v1.1 DONE
  • 8a7a5b47cd984c80c71332b6b2171fc298183bdf docs(planning): mark Phase 4 Extraction Sources complete
  • 8b1bc1b25ab070575e0c3f712c8d1b535830185c docs(web): bootstrap the first owner with its IdP subject
  • 5dd6e30aed19ae42349672d441c095bb6965da5c docs(web): document the session design and the production run command
  • 6101fff1c2a13b8fbb54f1cad15c9e239d81fe0e docs(web): name TRUSTED_PROXIES as the API setting for the web subnet
  • 428e11c5d632832b5d40d807758c3de9eb52f20c docs(web): point the build step at scripts/build-web-image.sh
  • 5ed2f334069982280b020a3b9ebb25fda93b8597 documents: alert after consecutive renderer timeouts, report it in /health
  • 2cadb74537ac95ffff99db2392de949dc338687e documents: fair shares, rate limit, atomic audit, per-route deadlines
  • 9b8ea1dff4ae39280e17e79455193e045e1b9b16 documents: re-encode renderer PNGs; socket must be a socket of the renderer uid
  • 8a45e16c1d1966c175a636bad7c6dd208cbaec29 documents: revoke and its audit row commit in one transaction
  • 9df7e891d5528e3d2fc2326a9943c9b64dab0bf0 documents: tile the watermark diagonally across the whole page
  • fe471aebd163e70c4371adfa1d24efaf74c3ab04 feat(api): ADM-01..09 admin API endpoints
  • 26334e3e61fca91f94655a800fc1fa8a185100dc feat(api): DIAG-01..03 diagnostics endpoints
  • b919a5ca31fbebac7bfe9b2b27f93b38b2ccfada feat(api): INJ-06 server-side webhook push
  • 4f11e57b6969e987edc1fe039363bd9a979d1100 feat(api): partial, conditional updates for secrets, JKS and YubiKeys
  • b316368c599556757fa07c79dae3c5ee48d1517f feat(api-server): bootstrap-user command for the first owner
  • 970a50cb039de980f65fcfe0b6da68d269c8486d feat(api-server): purge expired CLI auth rows every 15 minutes (L5)
  • 071e0bedeb9bcb99c3a98e3fe175517915447612 feat(auth): CLI SSO login with PKCE codes and rotating refresh tokens
  • 14d13fd25416f3fc27d790442ebab85ff8b550e6 feat(cli): ADM-01..09 ss admin subcommands
  • b7ba9e3f49d35b466b813a8bfdb174eaefc72d36 feat(cli): DIAG-04..05 ss doctor and ss trace
  • 1e87e1278e277c0f44d0c2cbf74405b5c980e97d feat(cli): EXT-01..07 extraction source importers
  • 8e3cb137bef31d984898496c70e03d9e05d69c74 feat(cli): INJ-01..05 inject subcommand (ssh/env/file/pipe/http)
  • a9ad82adcf749a8c0db27d1a7a0bc0c1a5a625ba feat(cli): ss login browser SSO, auth status/print-access-token, logout
  • e1316c523f4cc3edac8e6923569a3fb9b5e8c175 feat(db): OPS-03 secret TTL expiry background job
  • a86d36d3c82e986bd6cdf642b8e0446a4ae47b1b feat(k8s): OPS-05 NetworkPolicy for pod isolation
  • a98ad605fa0abac7cb5721e11290359acb69f19f feat(metrics): OPS-01 Prometheus metrics endpoint + OPS-02 trace ID propagation
  • 3906052df0a01e488faee85d143c02c55d10ca26 feat(rotation): OPS-04 secret rotation engine
  • d7d81cf799e06ec4ed75df304ef27bceb558a44c feat(sdk): TokenProvider and ss login CLI credentials
  • a177af3b0d717ba62186f5bb8a580a802904fd36 feat(sdk,cli): partial, conditional secret updates; redact reflected keys
  • f8b006bacb264661758e16b2a5df8f2dcddb7afb feat(sharing): share with a same-tenant user by email
  • a1527aab5f8ca7f9b168581461a70b7fb7853539 feat(web): friendly messages for /auth/callback?error=
  • fcfdbea859b51c3623c4fa24b7e33f3abb1b4ad2 feat(web): manage stored API tokens on /api-tokens
  • 9b73282529335f92c963b27ef31304855e49eaea feat(web): return to an allowlisted page after sign-in
  • f47bb1171d94d916cb108206d68ebf2bc7204d6a feat(web): server-side session cookie and same-origin API proxy
  • 2225f82293d1ca08cfbfa99f7f3e0f63b5cb56a9 feat: API enhancements and Docker build improvements
  • 5259a2d35c075e515c04f47a805a20519eb18756 feat: Add CLI intelligence, SAML/OIDC types, Terraform provider, Ansible plugin, and ssd daemon
  • f559dbcc036077fcc4b78d7f6927f59abd7edd96 feat: Add JKS keystore support with raw upload and managed entry modes
  • 226f7463cc2295cda0cc89f0263c2e7bb5...
Read more